IP Library › Granted Patent US 11,553,342
Granted Patent B2
US 11,553,342 · App. 16/929,048 · Granted Jan 10, 2023

Methods, systems, and computer readable media for mitigating 5G roaming security attacks using security edge protection proxy (SEPP)

Inventors: Shashikiran Bhalachandra Mahalank (Bangalore, IN); Jay Rajput (Bangalore, IN)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04W12/08H04L67/141H04W8/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,553,342
App. No.
16/929,048
Granted
Jan 10, 2023
Kind
B2
Abstract

A method for mitigating a 5G roaming attack using a security edge protection proxy (SEPP), includes receiving, at an SEPP, user equipment (UE) registration messages for outbound roaming subscribers. The method further includes creating, in a SEPP security database, UE roaming registration records derived from UE registration messages. The method further includes receiving, at the SEPP, a packet data unit (PDU) session establishment request message. The method further includes performing, using at least one parameter value extracted from the PDU session establishment request message, a lookup in the SEPP security database for a UE roaming registration record. The method further includes determining, by the SEPP and based on results of the lookup, whether to allow or reject the PDU session establishment request message.

Claims (50)

1. A method tor mitigating a 5G roaming attack using a security edge protection proxy (SEPP), the method comprising:

receiving, at an SEPP, user equipment (UE) registration messages for outbound roaming subscribers, wherein receiving the UE registration messages for the outbound roaming subscribers includes receiving N udm _UECM_Registration messages from access and mobility management functions (AMFs) and session management functions (SMFs) serving the outbound roaming subscribers;

creating, in a SEPP security database, UE roaming registration records derived from UE registration messages;

receiving, at the SEPP, a packet data unit (PDU) session establishment request message;

performing, using at least one parameter value extracted from the PDU session establishment request message, a lookup in the SEPP security database for a UE roaming registration record; and

determining, by the SEPP and based on results of the lookup, whether to allow or reject the PDU session establishment request message.

2. The method of claim 1 wherein creating records in the SEPP security database includes creating records that each include a subscription permanent identifier (SUPI) or subscription concealed identifier (SUCI), serving public land mobile network (PLMN) ID, and access type.

3. A method for mitigating a 5G roaming attack using a security edge protection proxy (SEPP), the method comprising:

receiving, at an SEPP, user equipment (UE) registration messages for outbound roaming subscribers;

creating, in a SEPP security database, UE roaming registration records derived from UE registration messages, wherein creating records in the SEPP security database includes creating records that each include a subscription permanent identifier (SUPI) or subscription concealed identifier (SUCI), serving public land mobile network (PLMN) ID, and access type;

receiving, at the SEPP, a packet data unit (PDU) session establishment request message, wherein receiving a PDU session establishment request message includes receiving a PDU session establishment request message including a SUPI or SUCI, a PLMN ID, and an access type;

performing, using at least one parameter value extracted from the PDU session establishment request message, a lookup in the SEPP security database for a UE roaming registration record; and

determining, by the SEPP and based on results of the lookup, whether to allow or reject the PDU session establishment request message.

4. The method of claim 3 wherein performing the lookup in the SEPP security database include performing the lookup using the SUPI or SUCI from the PDU session establishment request message.

5. The method of claim 4 comprising failing to locate a record corresponding to the SUPI or SUCI from the PDU session establishment request message in the SEPP security database, wherein determining whether to allow or reject the PDU session establishment request message includes determining to reject the PDU session establishment request message, and further comprising rejecting the PDU session establishment request message.

6. The method of claim 4 comprising locating a record corresponding to the SUPI or SUCI from the PDU session establishment request message in the SEPP security database, determining that a PLMN ID or an access type in the record does not match the PLMN ID or the access type in the PDU session establishment request message, wherein determining whether to allow or reject the PDU session establishment request message includes determining to reject the PDU session establishment request, and further comprising rejecting the PDU session establishment request message.

7. The method of claim 6 wherein rejecting the PDU session establishment request message includes discarding the PDU session establishment request message and sending a PDU session establishment error response.

8. The method of claim 4 comprising locating a record corresponding to the SUPI or SUCI from the PDU session establishment request message in the SEPP security database, determining that a PLMN ID and an access type in the record does match the PLMN ID and the access type in the PDU session establishment request message, wherein determining whether to allow or reject the PDU session establishment request message includes determining to allow the PDU session establishment request message, and further comprising allowing the PDU session establishment request message.

9. The method of claim 8 wherein allowing the PDU session establishment request message includes forwarding the PDU session establishment request message from the SEPP to a home session management function (hSMF).

10. A system for mitigating a 5G roaming attack, the system comprising:

a security edge protection proxy (SEPP) including at least one processor and a memory;

an SEPP security database implemented in the memory;

an SEPP roaming security controller implemented by the at least one processor for receiving user equipment (UE) registration messages for outbound roaming subscribers;

creating, in the SEPP security database, UE roaming registration records derived from UE registration messages;

receiving a packet data unit (PDU) session establishment request message;

performing, using at least one parameter value extracted from the PDU session establishment request message, a lookup in the SEPP security database for a UE roaming registration record;

determining, by the SEPP and based on results of the lookup, whether to allow or reject the PDU session establishment request message; and

wherein the SEPP roaming security controller is configured to receive Nudm_UECM_Registration messages from access and mobility management functions (AMFs) and session management functions (SMFs) serving the outbound roaming subscribers.

11. The system of claim 10 wherein the SEPP roaming security controller is configured to create the records in the SEPP security database where each includes a subscription permanent identifier (SUPI) or subscription concealed identifier (SUCI), serving public land mobile network (PLMN) ID, and access type.

12. A system for mitigating a 5G roaming attack, the system comprising:

a security edge protection proxy (SEPP) including at least one processor and a memory;

an SEPP security database implemented in the memory;

an SEPP roaming security controller implemented by the at least one processor for receiving user equipment (UE) registration messages for outbound roaming subscribers;

creating, in the SEPP security database, UE roaming registration records derived from UE registration messages;

receiving a packet data unit (PDU) session establishment request message;

performing, using at least one parameter value extracted from the PDU session establishment request message, a lookup in the SEPP security database for a UE roaming registration record;

determining, by the SEPP and based on results of the lookup, whether to allow or reject the PDU session establishment request message;

wherein the SEPP roaming security controller is configured to create the records in the SEPP security database where each includes a subscription permanent identifier (SUPI) or subscription concealed identifier (SUCI), serving public land mobile network (PLMN) ID, and access type; and

wherein the PDU session establishment request message includes a SUPI or SUCI, a PLMN ID, and an access type.

13. The system of claim 12 wherein the SEPP roaming security controller is configured to perform the lookup in the SEPP security database using the SUPI or SUCI from the PDU session establishment request message.

14. The system of claim 13 wherein the SEPP roaming security controller is configured to, in response to failing to locate a record corresponding to the SUPI or SUCI from the PDU session establishment request message in the SEPP security database, reject the PDU session establishment request message.

15. The system of claim 13 wherein the SEPP roaming security controller is configured to, in response to locating a record corresponding to the SUPI or SUCI from the PDU session establishment request message in the SEPP security database and determining that a PLMN ID or an access type in the record does not match the PLMN ID or the access type in the PDU session establishment request message, reject the PDU session establishment request message.

16. The system of claim 15 wherein the SEPP roaming security controller is configured to reject the PDU session establishment request message by discarding the PDU session establishment request message and sending a PDU session establishment error response.

17. The system of claim 13 wherein the SEPP roaming security controller is configured to, in response to locating a record corresponding to the SUPI or SUCI from the PDU session establishment request message in the SEPP security database, determining that a PLMN ID and an access type in the record matches the PLMN ID and the access type in the PDU session establishment request message, allow the PDU session establishment request message, wherein allowing the PDU session establishment request message includes forwarding the PDU session establishment request message from the SEPP to a home session management function (hSMF).

18. A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising:

receiving, at a security edge protection proxy (SEPP), user equipment (UE) registration messages for outbound roaming subscribers, wherein receiving the UE registration messages for the outbound roaming subscribers includes receiving N udm _UECM_Registration messages from access and mobility management functions (AMFs) and session management functions (SMFs) serving the outbound roaming subscribers;

creating, in a SEPP security database, UE roaming registration records derived from UE registration messages;

receiving, at the SEPP, a packet data unit (PDU) session establishment request message;

performing, using at least one parameter value extracted from the PDU session establishment request message, a lookup in the SEPP security database for a UE roaming registration record; and

determining, by the SEPP and based on results of the lookup, whether to allow or reject the PDU session establishment request message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2020
From: MAHALANK, SHASHIKIRAN BHALACHANDRA; RAJPUT, JAY
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 053216/0562 →
Continuity (1)
Related Publication 20220022040A1 · Jan 20, 2022
Cited By (6)
US 12,425,863 US 12,470,592 US 12,490,089 US 12,531,894 US 12,720,303 US 12,739,642